Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2015-9169
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 400…
Msm8909w Firmware
Mitigation only
HIGH 7.5
CVE-2015-9119
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDM9625, MD…
Mdm9206 Firmware
Mitigation only
HIGH 7.5
CVE-2015-9123
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile, Snapdragon Wear, and Small Cell SoC FSM9055, IPQ4019, MDM…
Mdm9206 Firmware
Mitigation only
HIGH 7.5
CVE-2014-10062
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9640, MDM9650, MS…
Mdm9206 Firmware
Mitigation only
HIGH 7.5
CVE-2014-10047
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400 and SD 800, when writing the Full Disk Encryption k…
Sd 400 Firmware
Mitigation only
HIGH 7.5
CVE-2014-10055
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400 and SD 800, there could be leakage of protected con…
Sd 400 Firmware
Mitigation only
HIGH 7.5
CVE-2018-10189
An issue was discovered in Mautic 1.x and 2.x before 2.13.0. It is possible to systematically emulate tracking cookies per contact due to tracking th…
Mautic
2.13.0+
HIGH 8.8
CVE-2018-5430 KEVEPSS 50%
The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server fo…
Jasperreports Server
after 6.4.2
MEDIUM 5.3
CVE-2018-10178
The FromDocToPDF extension before 13.611.13.2303 for Chrome allows remote attackers to discover visited web sites via vectors involving a mostVisited…
Fromdoctopdf
13.611.13.2303+
CRITICAL 9.8
CVE-2018-10106
D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have permission bypass and information disclosure in /htdo…
Dir 815 Firmware
after 2.07.b01
MEDIUM 5.3
CVE-2018-1000169
An exposure of sensitive information vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in CLICommand.java and ViewOptionHandler…
Jenkins
after 2.107.1
MEDIUM 5.3
CVE-2014-1686
MediaWiki 1.18.0 allows remote attackers to obtain the installation path via vectors related to thumbnail creation.
Mediawiki
No fix yet
HIGH 7.8
CVE-2017-0361
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure flaw, where the api.log might contain passwords in plaintext.
Debian Linux
1.27.2 / 1.28.1+
MEDIUM 5.3
CVE-2018-10082
CMS Made Simple (CMSMS) through 2.2.7 allows physical path leakage via an invalid /index.php?page= value, a crafted URI starting with /index.php?mact…
Cms Made Simple
after 2.2.7
CRITICAL 9.8
CVE-2015-0152
D-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage of the ad…
Dir 815 Firmware
2.07.b01+
HIGH 7.5
CVE-2018-1086
pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove th…
Debian Linux
Mitigation only
HIGH 7.5
CVE-2014-6309
The HTTP and WebSocket engine components in the server in Kaazing Gateway 4.0.2, 4.0.3, and 4.0.4 and Gateway - JMS Edition 4.0.2, 4.0.3, and 4.0.4 a…
Kaazing Websocket Gateway
Mitigation only
HIGH 7.5
CVE-2017-6910
The HTTP and WebSocket engine components in the server in Kaazing Gateway before 4.5.3 hotfix-1, Gateway - JMS Edition before 4.0.5 hotfix-15, 4.0.6 …
Kaazing Gateway
4.4.2 / 4.5.3+
MEDIUM 5.3
CVE-2018-9842EPSS 16%
CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replaying a logon message.
Password Vault
9.7+
MEDIUM 5.9
CVE-2018-0018
On SRX Series devices during compilation of IDP policies, an attacker sending specially crafted packets may be able to bypass firewall rules, leading…
Junos
Patch available
MEDIUM 5.3
CVE-2018-10028
joyplus-cms 1.6.0 allows remote attackers to obtain sensitive information via a direct request to the install/ or log/ URI.
Joyplus Cms
Mitigation only
MEDIUM 5.7
CVE-2018-7930
The Near Field Communication (NFC) module in Mate 9 Huawei mobile phones with the versions before MHA-L29B 8.0.0.366(C567) has an information leak vu…
Mate 9 Firmware
Mitigation only
HIGH 7.5
CVE-2017-18072
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9640, MDM9650, QCA4531, QCA6…
Mdm9206 Firmware
Mitigation only
MEDIUM 5.3
CVE-2015-1957
IBM WebSphere MQ 7.5.x before 7.5.0.6 and 8.0.x before 8.0.0.3 allows remote authenticated users to obtain sensitive information via a man-in-the-mid…
Websphere Mq
7.5.0.6 / 8.0.0.3+
MEDIUM 5.3
CVE-2014-2078
The backend in Open-Xchange (OX) AppSuite 7.4.2 before 7.4.2-rev9 allows remote attackers to obtain sensitive information about user email addresses …
Open Xchange Appsuite
Mitigation only
HIGH 7.5
CVE-2015-0172
IBM Security SiteProtector System 3.0, 3.1.0 and 3.1.1 allows remote attackers to bypass intended security restrictions and consequently execute unsp…
Security Siteprotector System
No fix yet
MEDIUM 5.3
CVE-2018-9922
An issue was discovered in idreamsoft iCMS through 7.0.7. Physical path leakage exists via an invalid nickname field that reveals a core/library/weix…
Icms
after 7.0.7
CRITICAL 9.8
CVE-2018-9852
In Gxlcms QY v1.0.0713, Lib\Lib\Action\Home\HitsAction.class.php allows remote attackers to read data from a database by embedding a FROM clause in a…
Gxlcms Qy
No fix yet
HIGH 7.5
CVE-2018-9325
Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledge of pad names.
Etherpad
1.6.4+
MEDIUM 5.9
CVE-2014-2359
OleumTech Wireless Sensor Network devices allow remote attackers to obtain sensitive information about sensor nodes or spoof devices by reading clear…
Ft1 Firmware
Mitigation only